Internet Explorer Zonemapping Failed Due To The Error Listed Below
Contents |
5, 20160 Share 0 0 In this blog post we explain the Event id windows failed to apply the internet explorer zonemapping settings log file 1085 seeing when the Internet Explorer Site To Zone internet explorer zonemapping failed (no data) Assignment List GPO is used. This scenario applies to All Internet Explorer versions and Windows what is internet explorer zonemapping policy Operating Systems(Windows 7, Windows 2008 R2, Windows 8.1, Windows 2012 R2, Windows 10 IE11). When you examine the System-Eventlog, you may find the following event:
Internet Explorer Zonemapping Success (no Data)
Log Name: System Source: Microsoft-Windows-GroupPolicy Event ID: 1085 Level: Warning Description: Windows failed to apply the Internet Explorer Zonemapping settings. Internet Explorer Zonemapping settings might have its own log file. Please click on the "More information" link. Event Xml:
to execute I had the error below in my application eventlog. Event Type: Error Event Source: Userenv Event Category: None Event ID: 1085 Date: 30-09-2008 Time: 15:20:30 User: NT AUTHORITY\SYSTEM Computer: TBG-TS01 Description: The Group Policy applying internet explorer zonemapping policy hangs client-side extension Internet Explorer Zonemapping failed to execute. Please look for any errors reported earlier by
What Is Internet Zone Mapping
that extension. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. My problem was with my site to zone assignment list
4cfb60c1-faa6-47f1-89aa-0b18730c9fd3
I used a wildcard like this: "*microsoft.com" but what you need to do is this "*.microsoft.com" So it is safe to say that the documentation from microsoft needs some sort of an update stating that you can only https://blogs.msdn.microsoft.com/askie/2016/04/05/description-of-event-id-1085-from-internet-explorer-zonemapping/ use a wildcard infront of dot. Below is the microsoft explaination: This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. These zone numbers have associated security settings that apply to all of the sites in the zone. Internet Explorer has 4 security zones, numbered 1-4, and these are used by this policy setting to associate sites to zones. They are: (1) Intranet zone, (2) Trusted http://daily-it.blogspot.com/2008/09/solved-group-policy-client-side.html Sites zone, (3) Internet zone, and (4) Restricted Sites zone. Security settings can be set for each of these zones through other policy settings, and their default settings are: Trusted Sites zone (Low template), Intranet zone (Medium-Low template), Internet zone (Medium template), and Restricted Sites zone (High template). (The Local Machine zone and its locked down equivalent have special security settings that protect your local computer.) If you enable this policy setting, you can enter a list of sites and their related zone numbers. The association of a site with a zone will ensure that the security settings for the specified zone are applied to the site. For each entry that you add to the list, enter the following information: Valuename - A host for an intranet site, or a fully qualified domain name for other sites. The valuename may also include a specific protocol. For example, if you enter http://www.contoso.com as the valuename, other protocols are not affected. If you enter just www.contoso.com, then all protocols are affected for that site, including http, https, ftp, and so on. The site may also be expressed as an IP address (e.g., 127.0.0.1) or range (e.g., 127.0.0.1-10). To avoid creating conflicting policies, do not include additional characters after the domain such as trailing slashes or URL path. For example, policy settings for www.contoso.com and www.contoso.com/mail would be treated as the same pol
are trusted using the following group policy setting: Administrative Templates > Windows Components > Internet Explorer> Internet Control Panel > Security Page > Site to Zone Assignment List On all (XP/vista/win7) workstations http://www.networksteve.com/forum/topic.php/Windows_failed_to_apply_the_Internet_Explorer_Zonemapping_settin/?TopicId=61270&Posts=0 across the domain I'm getting the following error: Log Name: System Source: Microsoft-Windows-GroupPolicy Event https://www.experts-exchange.com/questions/24589795/Issues-with-trusted-sites-Group-Policy.html ID: 1085 Task Category: None Level: Warning Keywords: Description: Windows failed to apply the Internet Explorer Zonemapping settings. Internet Explorer Zonemapping settings might have its own log file. There's nothing either side of this error in the log that shines any more light on the issue. I know which group policy object its applying these settings but cant internet explorer find which of the entries in the site to zone assignment list is causing this issue. I looked in the Group Policy/Operational log but all I see is the following entry which says "completed" but is logged as an error: After some research I'm guessing that the issue is an incorrect wild-card. This is what my trusted sites list looks like (with names removed of course): http://servername.* *.internaldomain.com.au *.domain.com.au *.domain.* internet explorer zonemapping *.externaldomain.com *.domain.inernaldomain.com.au *.domain.* *.domain/name.* *.domain.inernaldomain.au* *.domain.com Is there something obviously incorrect here? Does anyone know where I could find an article that clearly outlines the acceptable wildcard syntax for the "Security page\ site to zone assignment list" group policy? Ive read every forum post, website and blog I could find on the internet but nothing is clear and I wasn't able to find an MS document that steps it out. I've also changed the existing list a number of times based on blog posts etc but had no luck. **Please Note** I dont want to change to a different method or have an intellectual debate re why I would have these sites/wildacrd/policy set. I'm really looking to see what entry is invalid and where the documentation is for this policy setting so i can make sure they are always correct in the future. thanks in advance for your time and assistance Simone PS: I've already read the following posts a number of times: I get no data but have identified the GP that is causing the issue: A test case for troubleshooting group policy application Event ID 1085 and 7016 - http://blogs.technet.com/b/askds/archive/2008/08/21/a-test-case-for-troubleshooting-group-policy-application-event-id-1085-and-7016.aspx I dont have any 2 letter domain names: Problems Adding Top-Level Domains to Zone Sites List - http://support.
for Help Receive Real-Time Help Create a Freelance Project Hire for a Full Time Job Ways to Get Help Ask a Question Ask for Help Receive Real-Time Help Create a Freelance Project Hire for a Full Time Job Ways to Get Help Expand Search Submit Close Search Login Join Today Products BackProducts Gigs Live Careers Vendor Services Groups Website Testing Store Headlines Experts Exchange > Questions > Issues with trusted sites Group Policy Want to Advertise Here? Solved Issues with trusted sites Group Policy Posted on 2009-07-21 Web Browsers Windows Server 2003 Active Directory 1 Verified Solution 3 Comments 2,611 Views Last Modified: 2013-12-08 My goal is to add 3 internal websites to the trusted zone in IE(7) on all domain clients using group policy. I have been successful at this using the GPO setting: User Configuration > Internet Explorer Maintenance > Security > Security zones and content ratings This successfully applied to client machines and works fine however, previously our old sys admin used a different way of adding the trusted sites. He used the GPO setting: User Configuration > Administrative templates > Windows components > Internet explorer > security page > sites to zone assignment list. Using this method also greys out the trusted sites config on the clients so non can be manually added. This does not matter to me. Any clients that had the old GPO applied will apply the new GPO but not the settings so no trusted site settings change and it stays greyed out. Any new clients that have not applied the old GPO apply the new one fine. I need to undo the old GPO before I apply the new one to these machines but I'm having problems. When the old GPO applies the event log on the client reports Event 1085 : "The group policy client side extension Internet Explorer Zonemapping failed to execute. An RSOP on the machine reports "Internet Explorer Zonemapping failed due to the error.....The parameter is incorrect" I have tried removing the settings from the old GPO and disabling the sites to zone assignment list but this doesn't undo the change the and the same errors occur. This GPO setting applies itself to the registry at HKEY_LOCAL_MACHINE\software\policies\m